2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-10484 | CRITICAL | 9.8 | 0.4% | Jan 17, 2026 | The Registration & Login with Mobile Phone Number for WooCommerce plugin for WordPress is vulnerable to Authentication B... |
| CVE-2025-15403 | CRITICAL | 9.8 | 0.5% | Jan 17, 2026 | The RegistrationMagic plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 6... |
| CVE-2025-14894 | CRITICAL | 9.8 | 0.6% | Jan 16, 2026 | Livewire Filemanager, commonly used in Laravel applications, contains LivewireFilemanagerComponent.php, which does not p... |
| CVE-2025-14510 | CRITICAL | 9.2 | 0.4% | Jan 16, 2026 | Incorrect Implementation of Authentication Algorithm vulnerability in ABB ABB Ability OPTIMAX.This issue affects ABB Abi... |
| CVE-2025-59870 | CRITICAL | 9.8 | 0.2% | Jan 16, 2026 | HCL MyXalytics is affected by improper management of a static JWT signing secret in the web application, where the secr... |
| CVE-2025-60021 | CRITICAL | 9.8 | 26.2% | Jan 16, 2026 | Remote command injection vulnerability in heap profiler builtin service in Apache bRPC ((all versions < 1.15.0)) on all ... |
| CVE-2025-62582 | CRITICAL | 9.8 | 0.5% | Jan 16, 2026 | Delta Electronics DIAView has multiple vulnerabilities. |
| CVE-2025-62581 | CRITICAL | 9.8 | 0.5% | Jan 16, 2026 | Delta Electronics DIAView has multiple vulnerabilities. |
| CVE-2025-65118 | CRITICAL | 9.3 | 0.3% | Jan 16, 2026 | The vulnerability, if exploited, could allow an authenticated miscreant (OS Standard User) to trick Process Optimizatio... |
| CVE-2025-64691 | CRITICAL | 9.3 | 0.3% | Jan 16, 2026 | The vulnerability, if exploited, could allow an authenticated miscreant (OS standard user) to tamper with TCL Macro scr... |
| CVE-2025-61937 | CRITICAL | 10 | 1.5% | Jan 16, 2026 | The vulnerability, if exploited, could allow an unauthenticated miscreant to achieve remote code execution under OS sys... |
| CVE-2025-14237 | CRITICAL | 9.8 | 0.9% | Jan 16, 2026 | Buffer overflow in XPS font parse processing on Small Office Multifunction Printers and Laser Printers(*) which may allo... |
| CVE-2025-14236 | CRITICAL | 9.8 | 0.8% | Jan 16, 2026 | Buffer overflow in Address Book attribute tag processing on Small Office Multifunction Printers(*) which may allow an at... |
| CVE-2025-14235 | CRITICAL | 9.8 | 0.8% | Jan 16, 2026 | Buffer overflow in XPS font fpgm data processing on Small Office Multifunction Printers and Laser Printers(*) which may ... |
| CVE-2025-14234 | CRITICAL | 9.8 | 0.8% | Jan 16, 2026 | Buffer overflow in CPCA list processing on Small Office Multifunction Printers and Laser Printers(*) which may allow an ... |
| CVE-2025-14233 | CRITICAL | 9.8 | 0.8% | Jan 16, 2026 | Invalid free in CPCA file deletion processing on Small Office Multifunction Printers and Laser Printers(*) which may all... |
| CVE-2025-14232 | CRITICAL | 9.8 | 0.8% | Jan 16, 2026 | Buffer overflow in XML processing of XPS file in Small Office Multifunction Printers and Laser Printers(*) which may all... |
| CVE-2025-14231 | CRITICAL | 9.8 | 0.8% | Jan 16, 2026 | Buffer overflow in print job processing by WSD on Small Office Multifunction Printers and Laser Printers(*) which may al... |
| CVE-2025-67822 | CRITICAL | 9.4 | 0.4% | Jan 15, 2026 | A vulnerability in the Provisioning Manager component of Mitel MiVoice MX-ONE 7.3 (7.3.0.0.50) through 7.8 SP1 (7.8.1.0.... |
| CVE-2025-70892 | CRITICAL | 9.8 | 0.4% | Jan 15, 2026 | Phpgurukul Cyber Cafe Management System v1.0 contains a SQL Injection vulnerability in the user management module. The a... |
| CVE-2025-67647 | CRITICAL | 9.1 | 0.5% | Jan 15, 2026 | SvelteKit is a framework for rapidly developing robust, performant web applications using Svelte. Prior to 2.49.5, Svelt... |
| CVE-2025-66417 | CRITICAL | 9.8 | 0.4% | Jan 15, 2026 | GLPI is a free asset and IT management software package. From 11.0.0, < 11.0.3, an unauthenticated user can perform a SQ... |
| CVE-2025-62193 | CRITICAL | 9.8 | 1.2% | Jan 15, 2026 | Sites running NOAA PMEL Live Access Server (LAS) are vulnerable to remote code execution via specially crafted requests ... |
| CVE-2025-67079 | CRITICAL | 9.8 | 0.4% | Jan 15, 2026 | File upload vulnerability in Omnispace Agora Project before 25.10 allowing attackers to execute code through the MSL eng... |
| CVE-2025-67084 | CRITICAL | 9.9 | 0.4% | Jan 15, 2026 | File upload vulnerability in InvoicePlane through 1.6.3 allows authenticated attackers to upload arbitrary PHP files int... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now